Privacy policy
Last updated: 22 September 2026
This notice describes what happens to personal data when you read this website. It was written from the site’s own source rather than from a template, so it says what actually happens — which is very little. The Proxia application that clinics log into is a separate service with its own agreement: no patient record, appointment or clinical document passes through these pages.
Who is responsible
The controller for everything described here — the company that decides why and how this website processes personal data — is:
Questions about this notice, and any request under the rights set out at the end of it, should go to that e-mail address.
- Company
- IPNET Technologies Sàrl
- Registered office
- Rte de Bordinette 13, 1094 Paudex
- Country
- Switzerland
- [email protected]
- Telephone
- +41217912190
What this website is
Every page here is a static file. There is no application server, no database and no account: the pages are built in advance and sent to your browser as HTML, so this site cannot, by construction, keep a record of you on our side.
That also marks the edge of this notice. It covers this website and nothing else — not the product, not the app, and not anything a clinic does inside it.
The contact form sends nothing
The form in the contact section is not connected to anything. There is no server behind it, no e-mail gateway and no form service: pressing «Send message» stops the browser reloading the page, and that is all it does. What you typed stays in the tab and is gone when you close it.
So there is nothing for us to receive, store, pass on or delete — we never see it. Until the form is wired up, please write or call using the details above; what you send us that way is covered by the next section.
When you write or call
If you send an e-mail or telephone us, we process what you choose to tell us — your name, your address or number, your practice, and whatever your message says — in order to answer it. The legal basis is Art. 6(1)(b) GDPR where your message concerns a contract or a quotation you asked for, and Art. 6(1)(f), our legitimate interest in replying to people who get in touch, in every other case.
Correspondence is kept for as long as it takes to deal with the matter, and afterwards only while a legal retention obligation or a possible legal claim still requires it.
What the web server records
The site is delivered by a hosting provider acting for us. Like every web server, it writes an access log: the IP address that made the request, the date and time, the page or file asked for, the response status, and the browser and operating system your browser announces. This is part of making the request work and cannot be turned off without turning off the site.
Those logs are not used to build a picture of individual visitors and are not joined to anything else. The legal basis is Art. 6(1)(f) GDPR — the legitimate interest in serving the site and keeping it secure — and the provider deletes them after its own standard period.
Cookies and local storage
Opened for the first time, this site stores nothing in your browser at all: no cookie, no local-storage entry, no fingerprint. That is not a setting you have to find — it is what the pages do.
Things appear only once you answer the cookie question, and what appears depends on your answer:
Clearing your browser’s site data removes all of it, and the question is asked again on your next visit.
- proxia.consent.analytics.v1 — a local-storage entry holding one word, «granted» or «denied». It is your own answer, kept so that you are not asked again on every page and so that the choice can be shown to have been made. It is not a cookie, it is never sent anywhere, and it identifies nobody.
- _ga and _ga_<property> — cookies set by Google Analytics, and only if you accepted it. They hold a randomly generated identifier that lets Google recognise the same browser again. Google sets them to expire after two years; refusing analytics, now or later, deletes them.
Analytics, and why it waits for you
We use Google Analytics 4 to count visits and see which pages get read. It loads only after you have accepted it: with no answer on file, or with a refusal, the script is never requested — so no cookie is set and no request reaches Google at all. That is stronger than the usual arrangement, in which the tag loads first and is then asked to behave itself, and it is the reason the banner exists.
Once you accept, Google receives your IP address, the pages you open here, the page that referred you, an approximate location worked out from the IP address, and the device, browser and language your browser reports. Google does not store the full IP address for Analytics 4 properties, but it does receive it in order to derive that location. We see only aggregated reports, we do not try to identify anyone from them, and there is nothing else on this site to join them to.
The legal basis is your consent — Art. 6(1)(a) GDPR, and Art. 5(3) of the ePrivacy Directive for storing the cookie. You can withdraw it at any time from «Cookie settings» in the footer of every page, which also deletes the cookies Google has already set. Withdrawing does not make what happened before it unlawful.
The map in the contact section
The contact section can show a Google map of where we are. It does not load with the page: you see a still panel with a button on it, and Google is contacted only when you press that button.
If you do press it, Google receives your IP address and your browser details in order to serve the map, and may set its own cookies while doing so. The legal basis is your consent, given by that click. The choice is deliberately not remembered — the map starts unloaded again on your next visit — so there is nothing stored about it and nothing to withdraw.
What this site does not load
Part of what a privacy notice has to cover is answered best by what is absent. On these pages there is:
- no advertising, no ad network, no remarketing or conversion tag;
- no social-media button, pixel or share widget;
- no chat widget, heatmap, session recorder or A/B testing tool;
- no content delivery network — the scripts, styles and images all come from this site;
- no web font fetched from Google or anyone else: both typefaces are served from this domain, so opening a page tells no font provider that you did;
- no profiling and no automated decision-making of the kind Art. 22 GDPR is about, and nothing collected here is ever sold or exchanged.
Who else sees anything, and where it goes
Two recipients, and no others: the hosting provider that serves these pages, as our processor, and Google — for the analytics and the map, and only if you allowed them.
Google Analytics is provided to us by Google Ireland Limited, which may pass data to Google LLC in the United States. The United States counts as adequate only for organisations certified under the EU–U.S. Data Privacy Framework; Google LLC is certified under it and under its Swiss counterpart, and Google’s data-processing terms additionally incorporate the European Commission’s standard contractual clauses. That is the legal footing for the transfer — and it is also part of what you are deciding when you answer the banner, because authorities in the United States may seek access to data held there under their own law.
How long anything is kept
Nothing here is kept indefinitely, and most of it is never created in the first place.
- Your answer to the cookie question: until you clear your browser’s site data, or until we have to ask a different question and the old answer stops applying.
- Analytics data: held by Google for the retention period set on the property — Google offers two or fourteen months for event-level data — after which it is deleted. We keep no copy of our own.
- Server logs: the hosting provider’s standard retention period, then deleted.
- Correspondence: as long as it takes to deal with it, then only as long as a legal obligation or a possible claim requires.
- The contact form: nothing at all, because nothing is sent.
Security
The site is served over HTTPS, so what passes between your browser and the server is encrypted in transit. That is most of what there is to secure here: there is no login to protect, no database to breach, and no personal data at rest on our side beyond the server logs described above.
Swiss law and European law, both
The company is Swiss, so the revised Federal Act on Data Protection (FADP, the nLPD), in force since 1 September 2023, applies to this processing. The site is also addressed to practices and clinics in the European Union and the EEA and offers them goods and services, so the GDPR applies to the same processing under its Art. 3(2).
The two are close but not identical. Where they differ we apply whichever gives you more. The rights below are written in the GDPR’s vocabulary because it is the more detailed of the two; the FADP provides equivalents of substantially all of them, including access, rectification, erasure, objection and the handing over of your data.
Changes to this notice
This notice describes the site as it is built today. If a third party is ever added to it, this page changes before that goes live, and the date at the top changes with it. There is no mailing list to announce it on, so the date is the thing to check.
Your analytics choice
Your answer about analytics is stored in this browser. Opening the panel shows what it is right now and lets you change it: accepting and refusing are one click each, and refusing also deletes the cookies Google has already set.
Your rights
Where we process personal data about you, the GDPR gives you the rights below, and the Swiss FADP gives you equivalents of most of them. Exercising them is free, and exercising one is never held against you.
- Access
- To be told whether we process personal data about you and, if we do, to get a copy of it together with the information in this notice (Art. 15).
- Rectification
- To have inaccurate data about you corrected, and incomplete data completed (Art. 16).
- Erasure
- To have data about you deleted where it is no longer needed, where you withdraw the consent it rested on, or where you successfully object to it (Art. 17).
- Restriction
- To have processing limited to mere storage while a dispute about accuracy, or about an objection you made, is settled (Art. 18).
- Portability
- To receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent straight to another controller where that is technically feasible (Art. 20).
- Objection
- To object, on grounds relating to your particular situation, to processing we base on a legitimate interest — here, the server logs and our replies to your messages (Art. 21).
- Withdrawal of consent
- To withdraw consent at any moment, as easily as you gave it. For analytics that is the «Cookie settings» link in the footer of every page, and it takes effect at once. Withdrawing does not make what happened before it unlawful (Art. 7(3)).
- Complaint
- To lodge a complaint with a supervisory authority, without having to come to us first (Art. 77).
To use any of them, write to [email protected] and say which right you are exercising. We may ask for something that lets us be sure the request is yours, but only where there is genuine doubt and never more than is needed to settle it.
We answer within one month. If a request is unusually complex we may extend that by two further months, and we will tell you inside the first month if that happens.
If you are not satisfied, you can complain to a data protection authority. In the EU and the EEA that is the authority of the country where you live, where you work, or where you think the problem happened — the choice is yours. In Switzerland it is the Federal Data Protection and Information Commissioner (FDPIC) in Bern.